A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-42535 is a critical path handling vulnerability in Apache's mod_dav_fs module affecting versions 2.4.67 and earlier. This flaw allows WebDAV content authors to bypass access controls and directly manipulate trusted DAV property databases—metadata structures that Apache relies on for file handling and permission enforcement. When exploited, attackers can corrupt these databases, triggering child process crashes and potentially denying service to legitimate users. Organizations running Apache with WebDAV functionality enabled, particularly those using it for collaborative content management or file sharing, face immediate risk. The CVSS score of 9.1 reflects the severity: an authenticated attacker with content authoring privileges can cause significant operational disruption without requiring privilege escalation.
While CVE-2026-42535 doesn't map to specific MITRE ATT&CK techniques in its current classification, Casky.ai's extended reasoning capabilities would detect the underlying attack patterns within the vulnerability class. Practitioners should monitor for suspicious file system access attempts targeting DAV metadata directories (typically .htaccess or property storage locations), unusual process termination patterns in Apache child processes, and anomalous WebDAV PUT/MKCOL requests with malformed path parameters. Although Casky currently shows zero matching skills for this CVE, the platform's continuous skill mapping against CWE-668 (Exposure of Resource to Wrong Sphere) would flag similar path traversal and metadata manipulation attempts across your environment. Security teams should prioritize patching to 2.4.68 immediately and audit WebDAV access logs for any suspicious authoring activity preceding this advisory.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-42535. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation